Newgensoft develops a focused portfolio of enterprise document management, e-governance, and business process automation products such as OmniDocs, eGov, OmniApp, and OmniFlow that handle sensitive administrative and organizational workflows. Its vulnerabilities recur through access-control and data-handling weakness classes—improper access control, SQL injection, missing authorization, and resource-transfer issues—that reflect the authentication and database integration demands of document and process management platforms. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Newgensoft over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-35737HIGH In Correspondence Management System (corms) in Newgen eGov 12.0, an attacker can modify other users' profile information by manipulating the unvalidated UserIndex parameter, aka In | Dec 30, 2020 | 7.5 | 37 | NO | YES |
CVE-2011-3645HIGH Newgen OmniDocs allows remote attackers to bypass intended access restrictions via (1) a modified FolderRights parameter to doccab/doclist.jsp, which leads to arbitrary permission | Sep 27, 2011 | 7.5 | 36 | NO | YES |
CVE-2025-69908HIGH An unauthenticated information disclosure vulnerability in Newgen OmniApp allows attackers to enumerate valid privileged usernames via a publicly accessible client-side JavaScript | Jan 23, 2026 | 7.5 | 28 | NO | NO |
CVE-2010-0701HIGH SQL injection vulnerability in ForceChangePassword.jsp in Newgen Software OmniDocs allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | Feb 23, 2010 | 7.5 | 28 | NO | YES |
CVE-2025-65742HIGH An unauthenticated Broken Function Level Authorization (BFLA) vulnerability in Newgen OmniDocs v11.0 allows attackers to obtain sensitive information and execute a full account tak | Dec 15, 2025 | 8.2 | 25 | NO | NO |
CVE-2018-17791HIGH Newgen OmniFlow Intelligent Business Process Suite (iBPS) 7.0 has an "improper server side validation" vulnerability where client-side validations are tampered, and inappropriate i | Aug 21, 2019 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Newgensoft.
Media articles that mention a CVE ID that affects a product developed by Newgensoft — matched by CVE ID, not by vendor name.